以下是该漏洞描述的中文翻译: rclone 是一个用于在不同云存储提供商之间同步文件和目录的命令行程序。在 1.75.1 之前,rclone 核心在将源对象 值传递给目标后端(通过 、 、 和 等流程)时,未能在 机制生效前,拒绝源路径中包含的父目录段(如 )。 如果一个采用扁平键空间(flat-keepspace)的源对象存储库中由原生非 rclone 工具填充的数据中包含了原始的 键段,那么受影响的目标后端(包括 b2、swift、qingstor、oracleobjectstorage、internetarc
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88018 | 9.8 CRITICAL | rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signatu |
| CVE-2026-88044 | 9.1 CRITICAL | rclone: RC per-server auth-proxy bypass |
| CVE-2026-88045 | 7.5 HIGH | rclone: S3 multipart declared-length memory exhaustion |
| CVE-2026-88017 | 7.3 HIGH | rclone: FTP cross-session auth-proxy backend confusion |
| CVE-2026-88016 | 7.1 HIGH | rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclo |
| CVE-2026-88014 | 6.3 MEDIUM | rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive esca |
| CVE-2026-88015 | 5.3 MEDIUM | rclone local: crafted Range request against a translated symlink panics (DoS) |
| CVE-2026-88013 | 3.7 LOW | rclone: http backend forwards custom/auth headers to a different host on redirect |
No comments yet